PowerFlex: 4.X Outdated DES/3DES Ciphers In TLS/SSL On Port 6443

Summary: Outdated DES/3DES Ciphers in TLS/SSL on Port 6443

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

CVE-2016-2183

Monitoring tools may detect an increase in encrypted network traffic, particularly involving DES/3DES ciphers, which is atypical for regular operations. The PowerFlex system consistently fails certain security scans, especially those targeting encryption protocols, indicating the use of vulnerable DES/3DES ciphers.

In PFxM, the  kube-API pod listens on port 6443. 

4-5-mvm1:~ # ss -anp |grep 6443 |grep LIST
tcp           LISTEN             0               128                                                                            *:6443                                       *:*               users:(("kube-apiserver",pid=31133,fd=7))

 

Impact

Due to this vulnerability, the PowerFlex system fails to meet security compliance standards as evidenced by its inability to pass security assessments, such as Qualys scans.

Cause

The core issue stems from implementing the DES/3DES cipher within the TLS/SSL protocol in the PowerFlex system. DES (Data Encryption Standard) and 3DES (Triple DES) are encryption algorithms with known vulnerabilities and are considered outdated and insecure for modern cryptographic standards. In CVE-2016-2183, the flaw lies in how these ciphers are used in the encryption process, making them susceptible to specific types of cryptographic attacks. This vulnerability allows a man-in-the-middle attacker to intercept and decrypt portions of the data transmitted between the server and client, undermining the security of the communication.

https://access.redhat.com/security/cve/cve-2016-2183

https://www.cve.org/CVERecord?id=CVE-2016-2183

Resolution

Workaround

Upgrade PFxM to version 4.5.2 or higher. 

Impacted Versions

PFxM versions 4.5.1.x and lower

Fixed In Version

PFxM versions 4.5.2 and higher

Affected Products

PowerFlex appliance R650, PowerFlex appliance R640

Products

PowerFlex rack, VxFlex Ready Nodes, PowerFlex custom node, PowerFlex appliance R6525, PowerFlex appliance R660, PowerFlex appliance R6625, Powerflex appliance R750, PowerFlex appliance R760, PowerFlex appliance R7625, PowerFlex appliance R740XD , PowerFlex appliance R7525, PowerFlex appliance R840 ...
Article Properties
Article Number: 000223658
Article Type: Solution
Last Modified: 03 Feb 2025
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.